shioaji
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted financial data from external market feeds.
- Ingestion points: Market data ticks and bid/ask quotes are ingested via
STREAMING.md,MARKET_DATA.md, and historical queries inADVANCED.md. - Boundary markers: There are no specific instructions or delimiters to isolate or ignore potentially malicious instructions embedded within the market data streams.
- Capability inventory: The skill enables the agent to place financial orders (
api.place_order), modify trades, and interact with local project files viauv. - Sanitization: The ingested market data is processed without visible validation or sanitization before being potentially incorporated into agent decision-making processes.
- [EXTERNAL_DOWNLOADS]: The skill facilitates the download and installation of necessary development tools and libraries.
- Downloads the
uvinstallation script from Astral's official domain to manage the Python environment. - Recommends installing the
shioajiAPI library from standard package registries and Docker Hub. - Fetches official demo code from the Sinotrade GitHub repository.
- [COMMAND_EXECUTION]: The skill uses shell commands for environment configuration and script execution.
- Executes piped installation scripts for the
uvtool. - Uses
uv runandpip installto set up dependencies and execute trading workflows.
Audit Metadata